๐บ๐ธ
TPI-Abuse
2026-07-17 02:03:24
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.180.189.137 (ec2-35-180-189-137.eu-west-3.co ...
show more
(mod_security) mod_security (id:210492) triggered by 35.180.189.137 (ec2-35-180-189-137.eu-west-3.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 22:03:16.848156 2026] [security2:error] [pid 9390:tid 9596] [client 35.180.189.137:60358] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anglicancommission.com"] [uri "/.git/config"] [unique_id "almNZNkTGsAMdUiaf2O43gAAAQ8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 01:13:35
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.180.189.137 (ec2-35-180-189-137.eu-west-3.co ...
show more
(mod_security) mod_security (id:210492) triggered by 35.180.189.137 (ec2-35-180-189-137.eu-west-3.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 21:13:28.892958 2026] [security2:error] [pid 71091:tid 71091] [client 35.180.189.137:37920] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.carnegiepoint.com"] [uri "/.git/config"] [unique_id "almBuGEsyR947fVGwwp1BwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 23:48:04
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.180.189.137 (ec2-35-180-189-137.eu-west-3.co ...
show more
(mod_security) mod_security (id:210492) triggered by 35.180.189.137 (ec2-35-180-189-137.eu-west-3.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 19:47:55.925176 2026] [security2:error] [pid 7742:tid 7742] [client 35.180.189.137:59004] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.canergy.solar"] [uri "/.git/config"] [unique_id "alltq1fOWRwBRp2g_HQegQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-16 23:41:54
(2 weeks ago)
[da.kdns.gr] httpd-config-scan: sites=www.example.com; logs=/var/log/httpd/access_log; samples=/.git ...
show more
[da.kdns.gr] httpd-config-scan: sites=www.example.com; logs=/var/log/httpd/access_log; samples=/.git/config | /.env | /.env.local
show less
Hacking
Web App Attack
Anonymous
2026-07-16 16:56:48
(2 weeks ago)
(caddyscan) Scanner path probe from 35.180.189.137 (FR/France/ec2-35-180-189-137.eu-west-3.compute.a ...
show more
(caddyscan) Scanner path probe from 35.180.189.137 (FR/France/ec2-35-180-189-137.eu-west-3.compute.amazonaws.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 35.180.189.137 - - [16/Jul/2026:16:56:44 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 35.180.189.137 - - [16/Jul/2026:16:56:44 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 35.180.189.137 - - [16/Jul/2026:16:56:44 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 35.180.189.137 - - [16/Jul/2026:16:56:44 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 35.180.189.137 - - [16/Jul/2026:16:56:44 +0000] "GET /.env.staging HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-16 15:52:48
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.180.189.137 (ec2-35-180-189-137.eu-west-3.co ...
show more
(mod_security) mod_security (id:210492) triggered by 35.180.189.137 (ec2-35-180-189-137.eu-west-3.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 11:52:44.549464 2026] [security2:error] [pid 4505:tid 4505] [client 35.180.189.137:35684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.boulevardflowergardens.com"] [uri "/.git/config"] [unique_id "alj-TMhdoRsSOlA1-dXy-wAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-07-16 15:43:52
(2 weeks ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 13:50:26
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.180.189.137 (ec2-35-180-189-137.eu-west-3.co ...
show more
(mod_security) mod_security (id:210492) triggered by 35.180.189.137 (ec2-35-180-189-137.eu-west-3.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 09:50:19.326094 2026] [security2:error] [pid 9685:tid 9685] [client 35.180.189.137:33676] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.bnaior.org"] [uri "/.git/config"] [unique_id "aljhm05vgiXA1PzKx7xM1gAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Blexyel
2026-07-16 12:28:14
(2 weeks ago)
35.180.189.137 - - [16/Jul/2026:14:28:13 +0200] "GET /.git/config HTTP/1.1" 404 120 "-" "Mozilla/5.0 ...
show more
35.180.189.137 - - [16/Jul/2026:14:28:13 +0200] "GET /.git/config HTTP/1.1" 404 120 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 10:34:46
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.180.189.137 (ec2-35-180-189-137.eu-west-3.co ...
show more
(mod_security) mod_security (id:210492) triggered by 35.180.189.137 (ec2-35-180-189-137.eu-west-3.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 06:34:39.535433 2026] [security2:error] [pid 6804:tid 6804] [client 35.180.189.137:48046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.binfieldresources.com"] [uri "/.git/config"] [unique_id "alizv5tGEX4EVeDQ-16WaQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 08:30:16
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.180.189.137 (ec2-35-180-189-137.eu-west-3.co ...
show more
(mod_security) mod_security (id:210492) triggered by 35.180.189.137 (ec2-35-180-189-137.eu-west-3.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 04:30:11.088037 2026] [security2:error] [pid 26697:tid 26697] [client 35.180.189.137:39934] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.betnbet.ag"] [uri "/.git/config"] [unique_id "aliWkxyJZEq3QJ6vngBmGQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 07:57:39
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.180.189.137 (ec2-35-180-189-137.eu-west-3.co ...
show more
(mod_security) mod_security (id:210492) triggered by 35.180.189.137 (ec2-35-180-189-137.eu-west-3.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 03:57:34.988387 2026] [security2:error] [pid 31828:tid 31828] [client 35.180.189.137:41236] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.bestfriendz.us"] [uri "/.git/config"] [unique_id "aliO7q8XPIm9q6ygdnOePQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Antinson
2026-07-15 23:04:40
(2 weeks ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐ณ๐ฑ
homeshowdomain.nl
2026-07-15 22:00:38
(2 weeks ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-14.
show less
Web App Attack
SSH
Hacking
๐ณ๐ฑ
ipoac.nl
2026-07-15 15:11:26
(2 weeks ago)
-:443 35.180.189.137 - - [15/Jul/2026:17:11:25 +0200] - "GET /.git/config HTTP/1.1" 404 1961 "-" "Mo ...
show more
-:443 35.180.189.137 - - [15/Jul/2026:17:11:25 +0200] - "GET /.git/config HTTP/1.1" 404 1961 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Bad Web Bot